Hacker News
Security Vulnerability in Pioneer Rekordbox
j-scott
|next
[-]
"PRO DJ LINK" enables you to access rekordbox libraries (and load music files) remotely from other devices, whether that be on a computer or dedicated Pioneer/AlphaTheta hardware.
The vulnerability in question requires the attacker to be on the same local network as the instance of rekordbox and for the remote library feature to be enabled. Interested in the full writeup once it's released
peterlk
|root
|parent
|next
[-]
Rather than trying to make a new, shiny library, they should just release rekordbox 2.0, and then everyone would have a common lexicon to ask whether something is “rekordbox 2 compatible”. But instead we have this questionably compatible library plus as part of old, busted software that tries to brow best you into wrecking your old libraries.
I just use Claude to explain rekordbox to me now, and it is a bit more helpful than forums, though it also often gets confused from the conflicting advice/docs on the internet
MadnessASAP
|root
|parent
[-]
MadnessASAP
|root
|parent
|next
|previous
[-]
j-scott
|root
|parent
|next
[-]
I definitely would not have used this feature on a public network or exposed the mount to the open internet as well.
butterknife
|root
|parent
|next
|previous
[-]
chipheadi
|root
|parent
|next
[-]
The parity repair in the app should make the USB compatible with all CDJs because it makes both of the DBs identical.
I have also been able to repair the DBs that have been corrupted for example by disconnecting USB while Rekordbox is exporting to it.
I'm also just now building a website where you can send the DB repair requests for cases that need special attention.
butterknife
|root
|parent
[-]
chipheadi
|root
|parent
[-]
Added repair service for Rekordbox USBs: https://chiph.art/en/dj-usb-tkit/repair
brokenmachine
|root
|parent
|previous
[-]
Don't they bring their own setup?
hexfish
|next
|previous
[-]
brokenmachine
|next
|previous
[-]
I love it how they say to update, but there's no point because it won't fix the vulnerability anyway.
bpp
|previous
[-]
AlphaTheta (nee Pioneer DJ) makes arguably the best club DJ equipment – CDJs and mixers. Audiophiles may disagree but it's good enough that it's standard in all clubs, and artist riders (contracts) will absolutely require Pioneer CDJs if not their mixers as well. They're well made and great to perform on, and are basically advanced musical instruments at this point. If you know how to really use the equipment, you will be a better performer, and it's helpful to have a standard platform in all clubs.
But Rekordbox, which is required for those same performers to load their music onto USB drives and have them read it back with metadata etc., is one of the worst pieces of software I've ever used. It's clunky, it's slow to load the music, it often corrupts libraries or misplaces files. You'll load a song only to find that it inexplicably doesn't play. It'll hang for hours transferring a playlist that should be written in seconds. And they've just made it that much more complex by having a second library format, which they load in parallel, which has basically no benefit to the performer.
I have a friend who's a touring DJ who avoided updating Rekordbox for YEARS because his version was stable and he didn't want to introduce any variance into prep, because Rekordbox is so bad. If you tell a fellow DJ "Rekordbox ate my library" they will just shake their heads slowly, knowing that it's happened to them before and will happen to them again. It's a universal DJ experience.
It is completely unsurprising that this bug exists; I'd actually be surprised if their engineers put any thought into security at all. I bet Pro DJ Link just makes the drive available with no security whatsoever. The networks are typically just a few CDJs and lighting equipment, so the threat model is low. But this is obviously a real problem – just not one they probably put any thought into.
I would love to see this software replaced, but given their dominant market position I don't see how it will be.